All Apps and Add-ons

Splunk integration with Palo

lambap
New Member

Hello Splunk Community,

We are implementing splunk to integrate with palo alto firewalls. I have come across the following issues on Palo Alto add-on 6.0.2.

  1. Traffic Menu Item/drop down: we can see traffic data when running a splunk query but don't see a drop down for traffic and other day withing the Palo Alto app. Looking at some older deployments on youtube, that seems to be available. Can we get the same option in the newer version?

  2. Getting CPU/Palo Health data: How do we query that in splunk, is that part of syslog or snmp? Couldn't find an option to view CPU and other heath data in the add-on

  3. Query Palo Alto for live data: We need a dashboard that update every 5 minutes, that can grab running statistics. For example, NAT utilization, active clients connected to Global protect, etc. Basically have splunk run some commands in Palo to grab that data. Is there some documentation on how to achieve that?

0 Karma
Get Updates on the Splunk Community!

Improve Your Security Posture

Watch NowImprove Your Security PostureCustomers are at the center of everything we do at Splunk and security ...

Maximize the Value from Microsoft Defender with Splunk

 Watch NowJoin Splunk and Sens Consulting for this Security Edition Tech TalkWho should attend:  Security ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...